4 ms·
But... they didn't change their name on the form. They literally just said "I'm still me, but I want this other file now, please." All company data was, in OPs
by strofcon 5y ago
But... they didn't change their name on the form. They literally just said "I'm still me, but I want this other file now, please."
All company data was, in OPs scenario, made public to any and all authenticated users.
There is no way to rationally spin this as a malicious act, in my view.
- bawolff 5y agoWell they changed an id number. I guess the real life version would be changing the SSN number on the form.
- MangezBien 5y agoAn ssn is considered private info, the plan number wouldn't be.
- kelnos 5y agoI don't think simply changing the ID in the URL to see what would happen is itself a malicious act. But, after discovering the vulnerability, OP admitted to continuing to exploit the vulnerability so they could make use of the information they'd gotten, information that they should not have access to. That part of it is actively malicious.
- mcguire 5y agoNo one is claiming "I'm still me, but I want this other file now, please." is a malicious act. Downloading a number of them and comparing information, however, is not necessarily malicious but rather sketchy.